
Cybercriminals have been increasingly using Microsoft Teams as a channel for phishing individual employees using commercial Microsoft 365 accounts, often posing as a trusted party, such as someone from your internal IT department. These attacks leverage in-house chats being seen as more trustworthy than email, catching end users off-guard with what seems like an innocuous request for access, though often also promoting a sense of urgency to grant the other party permission quickly.
Below is a breakdown of why this shift happened, the different types of Teams phishing that have emerged over the past year, what your team should do when a request feels wrong and which controls reduce your risk at the account and device level:
Why Your Microsoft Teams Account is a Phishing Target
Microsoft 365 is one of the most popular business communication and productivity software suites for midmarket and enterprise businesses in the world, with Teams alone featuring hundreds of active users every month. This means that hackers have a large target base to work with from the start, although the chat application is still far from the top phishing vector, yet. There were millions of email compromise attempts versus thousands through Teams in the first half of 2026 – so, why worry about the latter at all?
Which would you be more likely to trust: a message from an account claiming to be your IT support on Outlook, or one popping up in what should be your internal company chat? Cybercriminals know that spoofed emails are a well-known and oversaturated method that most of their would-be victims are increasingly being trained to spot, but Teams phishing relies on most people unaware that chats and calls can be spoofed as well as an email. It is one of the fastest growing techniques of 2026 for this reason, with few immediate controls that could automatically block these sorts of attempts without also cutting off legitimate connectors.
Cost and effort on the attacker’s side are close to nothing, which also explains much of the growth in volume. A consumer email address is enough to register a Teams account and from there a threat actor can reach anyone whose organization allows outside accounts to open conversations without restriction. No exploit is involved and no inherent software flaw is being abused, so there is no quick patch to fix this gap.
Microsoft’s own Q2 2026 threat report shows how quickly this has scaled through 2026:
- Teams-based phishing detections rose 19% from March to April, held roughly flat into May, then increased another 10% into June
- Average weekly malicious call attempts rose 31% from April to May and another 27% into June, with the final two weeks of June recording the two highest weekly volumes on record
- Weekly voice phishing attempts have increased roughly 80% since the beginning of 2026 and now run at nearly ten times the mid-2025 baseline, the steepest growth of any threat category in the report
- Attackers concentrate the calls between 10:00am and 4:00pm Eastern on weekdays, with near-zero weekend activity, as that is when the person they are calling is most likely sitting at their desk
Types of Phishing Threats Seen in Teams Recently
Specific phishing threats for Microsoft Teams are continuously evolving and the exact methods that hackers use change fairly often. However, there are a few particular methods that make up the majority of those that have been observed increasing since last summer:
Impersonation of IT Support
Attackers posing as IT helpdesk support make up the dominant share of these attempts, typically warning of an account lockout that needs attention immediately. The conversation then moves to a request for approval, which across nearly every documented case takes one of three shapes: a multifactor prompt the employee accepts, a one-time passcode the employee reads aloud or a remote support session the employee opens themselves. While chats from outside accounts may display a warning banner, calls frequently do not, which means a call can feel more legitimate than the same approach delivered as a message. Attackers have also figured out how to avoid easy red flags on their account names, with generic names used climbing from 42 percent of these attempts in April to 52 percent by June, explicit IT support branding falling from 32 percent down to 16 percent and Helpdesk branding growing from 22 percent to 31 percent.
Compromise of a Trusted Account
A more concerning and more direct phishing attempt in Teams leverages an external account that has already been compromised but that would appear more trustworthy, typically one belonging to a partner or customer. The attacker would take advantage of this party having both access to and history with your chat communications, so a request or file attachment will not seem out of the ordinary. This technique essentially relies on the same social engineering practices hackers use with email or social media scams, but with the added benefit that many users are still unused to the same approach being used in a channel such as Microsoft Teams.
Voicemail Phishing (Vishing)
Beyond sending their requests via chat message, some threat actors are also directly calling users via Teams to impersonate IT personnel, taking advantage of the warning banner gap with calls to more successfully imitate a legitimate request. One ransomware group launched a campaign across the US and Canada using this technique, successfully infecting three confirmed victim organizations, with at least one of these attacks successfully encrypting the company’s files in under 17 hours.
Credential and Session Theft
A separate category bypasses the conversation entirely and goes after the sign-in itself, as with the subscription Kali365 phishing kit the FBI warned about in May 2026 that captures Microsoft 365 access and refresh tokens without ever touching the user’s password or triggering a multifactor challenge. Delivery in the documented cases came by email and not through Teams. At the same time, those tokens grant persistent access to Outlook, Teams and OneDrive together.
Email and Teams Phishing Simultaneously
Some threat actors are actively bombarding victims with attempts at phishing through email channels and Microsoft Teams to reinforce the legitimacy and urgency of their requests. This method still relies on impersonating IT helpdesk support in execution, but also targets the user with a sizable volume of spam emails, evidently to convince the victim to agree to the support request out of desperation. At least one cybercriminal group tracked by Google and Mandiant used this technique to infect several organizations with malware.
Fake Microsoft Store Updates
A more complex and multi-step campaign by one threat actor directed a victim towards a fraudulent Microsoft Store webpage that prompted them to update their Teams application, via a malicious attachment that was initially sent by email and ensured that the user was sent to the page of the attacker’s choosing. Once there, they downloaded what they assumed were legitimate updates after being prompted to – in actuality, the attacker installed remote monitoring and management (RMM) software on their computer.
What a Teams Impersonation Attempt Looks Like
Nearly every documented version of the impersonation attacks on Teams observed over the past year includes several of the following:
- An external tag on the chat or call, indicating the account sits outside your organization, which internal support will never carry
- Someone identifying themselves as IT for a ticket nobody at your company opened, which is backwards from how legitimate support engagements begin
- Pressure to act immediately, framed as an account lockout, a security alert or a compliance deadline
- A request to approve a multifactor prompt or read back a one-time code, neither of which any real support process requires
- A request to open a remote support session or install remote-control software during a first conversation
- A link or file nobody was expecting, particularly one presented as an update that has to be installed before something else will work
One of the easiest ways to catch these attempts, however, is in the method itself. Real IT support requests should originate from a case ticket you actually opened, and legitimate helpdesk engagements generally afford time to verify who is on the other end. A first-contact request that arrives with pressure attached is worth pausing on regardless of what it appears to ask for.
What You Should Do When an IT Support Request Feels Off
Here are three steps you should take immediately if you receive a sudden request from anyone claiming to be your IT support on Microsoft Teams:
- Stop – Approve nothing and install nothing until you have confirmed who is actually making the request
- Verify – Reach your support team through a channel you already use, such as a saved number or your ticket system
- Report – Tell your IT or helpdesk team right away, because the sooner they know the sooner an account can be locked
Adopting two additional practices also make it easier to verify legitimate requests if and when a hacker attempts to phish one of your employees via Teams:
- Publishing in advance how your support team contacts people and what they will never ask for removes the ambiguity these attempts leverage
- Setting a verbal verification word internally then gives your staff something concrete to request that a scammer would be able to produce
Reducing Phishing Risk at the Account and Device Level
No configuration change removes this category of risk on its own, because the attack turns on a person making a decision and not on a system being defeated. What these controls do is reduce how often an attempt reaches someone, limit what a single approval can accomplish and shorten the time an intrusion goes unnoticed. The goal is risk reduction rather than prevention, and the framing worth adopting is one that pairs proactive controls with the monitoring layer that catches what those controls do not:
Restricting Access at the Entry Point
Limiting Teams contact to an allowlist of trusted domains removes the entry point that these attempts rely on. The same logic applies to turning off the ability for outside accounts to open conversations, and to locking down guest access and anonymous meeting join at the tenant level. Remote support utilities are the other half of this. Quick Assist and comparable tools should be disabled or restricted to the roles that genuinely need them, with no legitimate session beginning without a ticket number attached to it.
Limiting What a Single Approval Reaches
Phishing-resistant multifactor authentication methods such as security keys and passkeys are considerably harder to socially engineer than an approval prompt somebody can be talked into accepting. Access policies requiring a compliant device before any administrative action or remote management session then contain what a single mistake is able to reach. Blocking device code authentication through policy closes an alternate path that a captured one-time code would otherwise open.
Catching an Intrusion Sooner
Identity, device and Teams activity need to be evaluated together so that a first-contact external chat followed by a remote session registers as one event and not as three unrelated log entries, with unusual approval patterns reviewed as a matter of course. Link checking at the moment of click, retroactive removal of messages later found malicious and active spoof detection all apply to Teams content and not only to email. Attack simulation tooling now covers simulated phishing delivered through Teams, which means your cybersecurity training can test people on the channel they are actually being approached through.
What Your Licensing Covers
Which of these settings you can apply depends partly on your M365 licensing, as several of the filtering and access policy controls sit in the higher plan tiers rather than in the base subscription. Putting them in place is generally a configuration project rather than an ongoing service, so it is worth confirming what your current subscription already entitles you to before purchasing anything additional.
What Happens After Someone Approves the Request
The controls above determine how often an attempt gets through, and what happens in the days afterward determines what it costs. Most of the financial and reputational damage in these incidents accumulates during that second interval, which is also the part businesses tend to plan for least. Even if a compromise does not get that, your business will still be exposed to significant financial risk, to say nothing of the reputational risk if and when data is exposed.
An attacker with access to an active mailbox can read through inbound and outbound messages for a wire transfer conversation with a vendor or client, alter the payment instructions on the outbound side and then step back while the funds move to an account they control. The same access becomes a distribution point for further phishing sent from a legitimate address to that person’s contacts, which quite a few recipients open because they recognize the sender. These are only two examples of methods that have been executed in the real world repeatedly – once a hacker gets into your network or systems, there are multiple ways they could capitalize on the intrusion, at your (figurative and literal) expense.
How CyberAssurance CORE™ Helps
CyberAssurance CORE™ is SWK Technologies’ managed cybersecurity program for small, mid-sized and small enterprise businesses, structured around the six functions of the NIST Cybersecurity Framework 2.0. Where the Microsoft 365 configuration work discussed above addresses this threat by tightening the environment itself, CyberAssurance CORE™ approaches it from a different direction, layering continuous monitoring, response and training on top of whatever controls are already in place.
The program is built to function as one system, so the analysts, tools and procedures inside of it operate as a coordinated ecosystem rather than as a collection of separate products your team has to manage on its own. Three core components of CyberAssurance CORE™ provide effective solutions to combating Teams phishing attacks:
- SIEM-backed monitoring captures the disparate activity generated across your network and flags the pattern of a compromised account, whether the compromise originated in email or in Teams.
- Security awareness training provides staff with the knowledge to spot these attempts, along with periodic testing to identify who is most likely to click through.
- Managed detection and response flags the follow-on activity of a threat actor attempting to install additional software on a compromised device.
A 24/7 security operations center sits behind all three, with the trained analysts who investigate what the monitoring layer surfaces and act on it when the situation calls for a response.
Reduce Your Microsoft Teams Risk with SWK Technologies
Attackers are working through the tools your staff already trust, and a Teams message asking for a quick approval does not look like a security event while it is happening. Reducing that risk means addressing both the moment of first contact and everything that follows it, which is what CyberAssurance CORE™ is built to do, pairing solutions and managed support that allow you to strengthen the human layer of your network security as well as shorten the window between compromise and containment.
Contact SWK here to learn how CyberAssurance CORE™ can help your business improve threat visibility and meet compliance requirements.
